Re: Email Web of Trust - Problem Statement
"Peter J. Holzer" <[email protected]> Tue, 9 Mar 2004 12:18:00 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On 2004-03-08 20:36:20 -0500, Yakov Shafranovich wrote: > Peter J. Holzer wrote: > >On 2004-03-08 17:21:34 -0500, Yakov Shafranovich wrote: > ... > >>>More generally, the trust could be based on a particular policy or set > >>>of policies: A particular domain, for example, might be trusted to > >>>adhere to certain antispam policies regarding UBE, authenticating > >>>senders, responding to complaints, etc. > >>> > >>>I think we need to resolve this question before discussing mechanisms. > >> > >>I was actually thinking of whether a specific domain is trusted to > >>provide non-forged data in SMTP, staying away from the definitions of > >>spam. > > > > > >How do you determine that? It is relatively simple to get an opinion > >(either from a user or a program like SpamAssassin) on whether a given > >message is spam or not. But whether the return-path is forged or not is > >an objective criterium which can not easily be verified. If you get a > >message from <[email protected]> from the MTA 143.130.50.112, is that > >forged or not? > > > > Isn't the whole point of a trust system is to provide a way to verify > something via a vouching mechanism rather than relying on a test by > SpamAssasin or a user? Yes, but somebody has to vouch, or else there are no vouchers to rely on. I feel comfortable in vouching that I have never received spam from a given MTA. I can do that manually by checking through my mail logs (which would be rather tedious). This can also be easily partially or fully automated. I do not feel comfortable vouching that a domain/MTA/organization doesn't send forged mails without knowing if and how they verify the sender. In general, I don't have that information, so I can't vouch for them. (In fact, it isn't even clear what a "forged mail" is - if I send a mail with a sender of <[email protected]> from the office instead of from home, is that forged? Some would say yes - I should only send as <[email protected]> through my employers MTA and only as <[email protected]> through my private MTA; but both addresses belong to me, so I wasn't lying about the sender, and the path a mail takes doesn't change the fact whether the mail itself is forged or not.) hp -- _ | Peter J. Holzer | I think we need two definitions: |_|_) | Sysadmin WSR | 1) The problem the *users* want us to solve | | | [email protected] | 2) The problem our solution addresses. __/ | http://www.hjp.at/ | -- Phillip Hallam-Baker on spam [demime 0.99d.1 removed an attachment of type application/pgp-signature]